System and method for role based access control of a document processing device
Abstract
The subject application is directed to a system and method for controlling access to a document processing device based on roles assigned to user groups. Each group of users has certain functions for which they are authorized to use a document processing device. The device determines the group to which the user belongs, and then determines those functions of the device for which the group is authorized. The device then compares the requested function with the authorized functions to determine if the group to which the user belongs is allowed to use the document processing device for the requested function. The document processing device then performs the authorized requested function or denies use of the device for an unauthorized function.
Claims
exact text as granted — not AI-modified1 . A system for controlling access to functionality of a document processing device based upon group membership, comprising:
means for receiving an electronic document into a document processing device, the document processing device including means for a plurality of document processing operations; means for receiving document processing instruction data corresponding to at least one user-selected document processing operation corresponding to at least one of the received electronic document and an associated tangible document; means for determining at least one function of the document processing device corresponding to the at least one user-selected document processing operation; means for acquiring user data representative of an identity of a user of the document processing device, which user data is associated with at least one of the received electronic document and the associated tangible document; means for determining at least one group of users associated with the user in accordance with the acquired user data; means for receiving device access data representative of device access privileges associated with each of a plurality of groups, wherein each group includes at least one associated user; means for retrieving a permission matrix template specifying at least one allowable document processing function of the document processing device associated with each of a plurality of roles, wherein each role includes at least one of a group and a user associated with usage of the document processing device; means for generating permission matrix data in accordance with the role associated with the at least one determined group and retrieved permission matrix template, the permission matrix data including data representative of allowable document processing functions of the document processing device from a plurality thereof by a user associated with the at least one determined group; means for storing the permission matrix on a data storage associated with the controller of the document processing device; comparison means, associated with a controller of the document processing device, for comparing the determined function and determined role with the stored permission matrix data; and means for controlling operation of the document processing device to a subset of available document processing functions in accordance with the stored permission matrix such that use of the document processing function is prevented when not permitted by the stored permission matrix.
2 . The system of claim 1 further comprising:
means for transmitting, via an associated network, acquired user data to an authentication server; means for transmitting, via the associated network, device access data to the authentication server;
wherein the authentication server compares the user data with the device access data to generate the permission matrix data.
3 . The system of claim 2 , further comprising:
means for receiving, at the authentication server, each determined function associated with the document processing instruction data; and means for testing each determined function against the permission matrix data associated with the determined group.
4 . The system of claim 3 , wherein the server further comprises means for communicating the permission matrix data to each of a plurality of document processing devices via the associated network.
5 . The system of claim 2 , further comprising means for generating control data for control of the document processing device in accordance with an output of the testing means.
6 . The system of claim 5 , further comprising:
means for transmitting, to the document processing device, control data representative of an allowed function in accordance with an output of the testing means; and means for transmitting, to the document processing device, control data representative of a denied function in accordance with an output of the testing means.
7 . The system of claim 6 , further comprising:
means for receiving control data from the authentication server; and wherein the document processing device is controlled in accordance with the received control data such that use of the document processing function is prevented when not permitted by the control data and use of the document processing function is enabled when permitted by the control data.
8 . The system of claim 7 , wherein the control data is communicated to each of a plurality of document processing devices via the network.
9 . A method for controlling access to functionality of a document processing device based upon group membership, comprising the steps of:
receiving an electronic document into a document processing device, the document processing device including a plurality of document processing functions; receiving document processing instruction data corresponding to at least one user-selected document processing operation corresponding to at least one of the received electronic document and an associated tangible document; determining at least one function of the document processing device corresponding to the at least one user-selected document processing operation; acquiring user data representative of an identity of a user of the document processing device, which user data is associated with at least one of the received electronic document and the associated tangible document; determining at least one group of users associated with the user in accordance with the acquired user data; receiving device access data representative of device access privileges associated with each of a plurality of groups, wherein each group includes at least one associated user; retrieving a permission matrix template specifying at least one allowable document processing function of the document processing device associated with each of a plurality of roles, wherein each role includes at least one of a group and a user associated with usage of the document processing device; generating permission matrix data in accordance with the role associated with the at least one determined group and retrieved permission matrix template, the permission matrix data including data representative of allowable document processing functions of the document processing device from a plurality thereof by a user associated with the at least one determined group; storing the permission matrix on a data storage associated with the controller of the document processing device; comparing, at a controller associated with the document processing device, the determined function and determined role with the stored permission matrix data; and controlling operation of the document processing device to a subset of available document processing functions in accordance with the stored permission matrix such that use of the document processing function is prevented when not permitted by the stored permission matrix.
10 . The method of claim 9 , further comprising the steps of:
transmitting, via an associated network, acquired user data to an authentication server; transmitting, via the associated network, device access data to the authentication server;
wherein the authentication server compares the user data with the device access data to generate the permission matrix data.
11 . The method of claim 10 , further comprising the steps of:
receiving, at the authentication server, each determined function associated with the document processing instruction data; and testing each determined function against the permission matrix data associated with the determined group.
12 . The method of claim 11 , further comprising the step of communicating the permission matrix data from the authentication server to each of a plurality of document processing devices via the associated network.
13 . The method of claim 10 , further comprising the step of generating control data for control of the document processing device in accordance with a result of the testing.
14 . The method of claim 13 , further comprising the steps of:
transmitting, to the document processing device, control data representative of an allowed function in accordance with a result of the testing; and transmitting, to the document processing device, control data representative of a denied function in accordance with a result of the testing.
15 . The method of claim 14 , further comprising the steps of:
receiving control data from the authentication server; and controlling the document processing device in accordance with the received control data such that use of the document processing function is prevented when not permitted by the control data and use of the document processing function is enabled when permitted by the control data.
16 . The method of claim 15 , further comprising the step of communicating the control data to each of a plurality of document processing devices via the network.Join the waitlist — get patent alerts
Track US2009119755A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.